Описание
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.
A denial of service flaw has been discovered in the node-static npm package. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the node server.
Отчет
The availability risk of this vulnerability is limited to the web server which incorporates the node-static package. The host system is not at risk.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | mozjs60 | Not affected | ||
| Red Hat Enterprise Linux 9 | gjs | Not affected | ||
| Red Hat Enterprise Linux 9 | polkit | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.
This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package fails to catch an exception when user input includes null bytes. This allows attackers to access http://host/%00 and crash the server.
This affects all versions of the package node-static; all versions of ...
@nubosoftware/node-static failure to catch exception can result in server crash
5.3 Medium
CVSS3